{"id":80550,"date":"2023-06-05T13:10:20","date_gmt":"2023-06-05T17:10:20","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=80550"},"modified":"2025-01-10T15:30:23","modified_gmt":"2025-01-10T20:30:23","slug":"configure-ade","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/configure-ade","title":{"rendered":"Configure Automated Device Enrollment"},"content":{"rendered":"\n

Remotely enroll macOS, iOS, and iPadOS devices in Mobile Device Management (MDM). Automated Device Enrollment (ADE) lets you automatically enroll devices into JumpCloud MDM during the device out-of-box experience. After devices are enrolled in JumpCloud MDM, IT Admins have management and configuration control over managed devices. With a customized setting, Zero-Touch Automated Device Enrollment Onboarding can also automatically bind the user to the device after authentication.\u200b\u200b\u200b\u200b\u200b<\/p>\n\n\n\n

First, you’ll configure ADE for your organization. Next, you’ll add your device to the MDM server. Then, you’ll sync the device with Apple. Finally, you’ll configure your end users’ zero-touch experience.<\/p>\n\n\n\n

    \n
  1. Configure ADE for your Organization<\/li>\n\n\n\n
  2. Add Device to the MDM Server<\/li>\n\n\n\n
  3. Sync Device to JumpCloud<\/li>\n\n\n\n
  4. Configure your End Users’ Experience<\/li>\n\n\n\n
  5. Renew Your Automated Device Enrollment Token Annually<\/li>\n<\/ol>\n\n\n\n

    Configure Automated Device Enrollment for your Organization<\/h2>\n\n\n\n
      \n
    1. Log in to the JumpCloud Admin Portal<\/a>.<\/li>\n\n\n\n
    2. Go to DEVICE MANAGEMENT<\/strong> > MDM<\/strong>.<\/li>\n\n\n\n
    3. On the MDM home page, click get started<\/strong> under Automated Device Enrollment Configuration<\/strong>.<\/li>\n\n\n\n
    4. \u200b\u200b\u200bIn Set Up Apple\u2019s Automated Device Enrollment<\/strong>, click download <\/strong>under Generate a Key<\/strong>. JumpCloud downloads a certificate that contains a key. Apple uses this to encrypt the Automated Device Enrollment token.<\/li>\n\n\n\n
    5. Under Sign in to Apple<\/strong>, click sign into Apple Business Manager<\/strong> and enter your credentials. If you have an education account, click sign into Apple School Manager<\/strong>.<\/li>\n\n\n\n
    6. Add your MDM server:<\/li>\n\n\n\n
    7. Select your profile name, then select Preferences<\/strong>.<\/li>\n\n\n\n
    8. Select MDM Server Assignment<\/strong>, then click Add MDM Server<\/strong>.<\/li>\n\n\n\n
    9. Enter a name for your company\u2019s MDM server and leave Allow this MDM Server to release devices<\/strong> selected.<\/li>\n\n\n\n
    10. Click Choose File<\/strong>.<\/li>\n\n\n\n
    11. Locate the jumpcloud-dep.pem file downloaded in Step 4, select it, and click Open<\/strong>.<\/li>\n\n\n\n
    12. Click Save<\/strong>.<\/li>\n\n\n\n
    13. Download the token by selecting the server and clicking Download Token<\/strong>, then clicking Download Server Token<\/strong>.<\/li>\n\n\n\n
    14. In the Admin Portal, go to Set Up Apple\u2019s Automated Device Enrollment<\/strong> and under Upload Automated Device Enrollment Token<\/strong>, install the new token by clicking Browse <\/strong>or dragging and dropping the server token for your MDM server. <\/li>\n\n\n\n
    15. Click complete setup<\/strong>.<\/li>\n<\/ol>\n\n\n\n

      See the Getting Started Guide for Apple Business Manager<\/a> to learn more about Apple\u2019s Automated Device Enrollment. <\/p>\n\n\n\n

      Add the Device to the MDM Server<\/h2>\n\n\n\n
        \n
      1. Log in to Apple Business Manager (ABM) or Apple School Manager (ASM).<\/li>\n\n\n\n
      2. Click Devices <\/strong>and select your device. You may want to search for it by serial number.<\/li>\n\n\n\n
      3. Click Edit MDM Server<\/strong>.<\/li>\n\n\n\n
      4. Select Assign to the following MDM<\/strong> and choose your MDM server from the list.<\/li>\n\n\n\n
      5. Click Continue<\/strong>, then click Confirm<\/strong>. <\/li>\n\n\n\n
      6. Verify that the device was added to your MDM server.<\/li>\n<\/ol>\n\n\n\n

        The sync process between Apple and JumpCloud ensures the device will contact JumpCloud\u2019s MDM server on first boot to enroll in MDM.<\/p>\n\n\n\n

        Sync the Device to JumpCloud<\/h2>\n\n\n\n

        <\/p><\/div>

        Tip:<\/strong> \n

        Perform these steps every time you add new devices in ABM or ASM.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n

          \n
        1. Log in to the JumpCloud Admin Portal<\/a>.<\/li>\n\n\n\n
        2. Go to DEVICE MANAGEMENT<\/strong> > MDM<\/strong>.<\/li>\n\n\n\n
        3. On the MDM home tab, click sync with Apple<\/strong> under Automated Device Enrollment Devices<\/strong> to ensure that your list of JumpCloud Automated Device Enrollment devices matches what is in ABM or ASM.<\/li>\n<\/ol>\n\n\n\n

          From here, you can configure your end users’ experience on company-owned Apple devices from day one. For macOS users, see Configure your macOS users’ zero-touch experience<\/a>. For iOS users, see Configure your iOS users’ zero-touch experience<\/a>.<\/p>\n\n\n\n

          Configure your End Users’ Experience<\/h2>\n\n\n\n

          Configure your macOS users’ zero-touch experience<\/strong>:<\/p>\n\n\n\n

            \n
          1. Log in to the JumpCloud Admin Portal<\/a>.<\/li>\n\n\n\n
          2. Go to DEVICE MANAGEMENT<\/strong> > MDM<\/strong>.<\/li>\n\n\n\n
          3. On the Apple<\/strong> tab, under Automated Device Enrollment Configuration<\/strong>, click Configure MacOS<\/strong> to configure your zero-touch experience.<\/li>\n\n\n\n
          4. Configure the Default Group Association<\/strong>. \n